Authentication for devices with non-cellular access

By sending a registration request for the third device to the second device, and sending security information to the fourth device after receiving the authentication message, the problem of difficulty in authenticating or authorizing non-cellular access devices in the prior art is solved, and effective authentication and secure connection establishment of devices such as AUN3 devices are realized.

CN119999248APending Publication Date: 2025-05-13NOKIA TECHNOLOGIES OY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380071171.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-08-08
Filing Date
2023-08-07
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

It is difficult for the prior art to effectively authenticate or authorize devices with non-cellular access, especially AUN3 devices, to cover the authentication or authorization requirements of non-3GPP devices.

Method used

By means and method, a registration request for the third device is sent to the second device, indicating that it is accessing the network through a non-cellular mechanism. Then, upon receiving the authentication message, security information for establishing the connection is sent to the fourth device.

Benefits of technology

Effective authentication and authorization of devices with non-cellular access is realized, the security of data communication is ensured, and a secure connection can be established to protect communication security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119999248A_ABST
    Figure CN119999248A_ABST
Patent Text Reader

Abstract

Example embodiments of the present disclosure relate to authentication for devices with non-cellular access. A first device transmits a registration request for a third device to a second device. The registration request indicates at least that the third device is accessing the network via a non-cellular mechanism. The first device also receives, from the second device, a first message indicating that the third device is authenticated. Based on the reception of the first message, the first device also sends to the fourth device security information for establishing a connection between the third device and the fourth device. In this manner, the third device may be authenticated. In addition, a secure connection between the third device and the fourth device may be established.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Various example embodiments of the present disclosure relate generally to the field of telecommunications, and more particularly to methods, devices, apparatus, and computer-readable storage media for authentication for devices with non-cellular access. Background Art

[0002] With the rapid development of communication technology, communication systems can support various access technologies for terminal devices. For example, terminal devices can be connected to communication networks via cellular access mechanisms such as the third generation partnership project (3GPP) access mechanism. Alternatively, in some scenarios, terminal devices can be connected to communication networks via non-cellular access mechanisms (such as non-3GPP access mechanisms). In recent communication technologies, it has been proposed that terminal devices that access the network via non-cellular mechanisms need to be authenticated or registered with the network before performing communication. Such authentication or registration processes can ensure the security of data communications. Authentication for devices with non-cellular access is being introduced. Summary of the invention

[0003] In a first aspect of the present disclosure, a first device is provided. The first device includes at least one processor; and at least one memory storing instructions, which, when executed by the at least one processor, causes the first device to at least perform: sending a registration request for a third device to a second device, the registration request at least indicating that the third device is accessing a network via a non-cellular mechanism; receiving a first message indicating that the third device is authenticated from the second device; and based on the reception of the first message, sending security information for establishing a connection between the third device and the fourth device to a fourth device.

[0004] In a second aspect of the present disclosure, a second device is provided. The second device includes at least one processor; and at least one memory storing instructions, which, when executed by the at least one processor, causes the second device to at least perform: receiving a registration request for a third device from a first device, the registration request at least indicating that the third device is accessing a network via a non-cellular mechanism; sending an authentication request for the third device to a fifth device, the authentication request at least indicating that the third device is accessing a network via a non-cellular mechanism; and sending a first message indicating that the third device is authenticated to the first device.

[0005] In a third aspect of the present disclosure, a third device is provided. The third device includes at least one processor; and at least one memory storing instructions, which, when executed by the at least one processor, causes the third device to at least perform: sending a message to at least one of the first device or the fourth device, the message at least indicating that the third device is accessing a network via a non-cellular mechanism; determining security information for establishing a connection between the third device and the fourth device; and performing a process with the fourth device to establish a connection based on the security information.

[0006] In a fourth aspect of the present disclosure, a fourth device is provided. The fourth device includes at least one processor; and at least one memory storing instructions, which, when executed by the at least one processor, causes the fourth device to at least perform: receiving security information for establishing a connection between a third device and the fourth device from a first device; and executing a process with the third device based on the security information to establish a connection.

[0007] In a fifth aspect of the present disclosure, a fifth device is provided. The fifth device includes at least one processor; and at least one memory storing instructions, which, when executed by the at least one processor, causes the fifth device to at least perform: receiving a first authentication request for a third device from a second device, the first authentication request at least indicating that the third device is accessing a network via a non-cellular mechanism; and sending a second authentication request for the third device to a sixth device.

[0008] In a sixth aspect of the present disclosure, a method is provided. The method includes: sending a registration request for a third device from a first device to a second device, the registration request at least indicating that the third device is accessing a network via a non-cellular mechanism; receiving a first message from the second device indicating that the third device is authenticated; and based on the reception of the first message, sending security information for establishing a connection between the third device and the fourth device to a fourth device.

[0009] In a seventh aspect of the present disclosure, a method is provided. The method includes: receiving, by a second device, a registration request for a third device from a first device, the registration request at least indicating that the third device is accessing a network via a non-cellular mechanism; sending an authentication request for the third device to a fifth device, the authentication request at least indicating that the third device is accessing the network via a non-cellular mechanism; and sending a first message to the first device indicating that the third device is authenticated.

[0010] In an eighth aspect of the present disclosure, a method is provided. The method includes: sending a message from a third device to at least one of a first device or a fourth device, the message at least indicating that the third device is accessing a network via a non-cellular mechanism; determining security information for establishing a connection between the third device and the fourth device; and performing a process with the fourth device to establish a connection based on the security information.

[0011] In a ninth aspect of the present disclosure, a method is provided, comprising: receiving, by a fourth device from a first device, security information for establishing a connection between a third device and a fourth device; and executing a process with the third device based on the security information to establish a connection.

[0012] In a tenth aspect of the present disclosure, a method is provided. The method includes: receiving, by a fifth device, a first authentication request for a third device from a second device, the first authentication request at least indicating that the third device is accessing a network via a non-cellular mechanism; and sending a second authentication request for the third device to a sixth device.

[0013] In an eleventh aspect of the present disclosure, a computer-readable medium is provided, wherein the computer-readable medium includes instructions stored thereon, and the instructions are used to cause a device to at least execute the method according to the sixth aspect, the seventh aspect, the eighth aspect, the ninth aspect, or the tenth aspect.

[0014] It should be understood that the invention summary is not intended to identify the key or essential features of the embodiments of the present disclosure, nor is it intended to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Some example embodiments will now be described with reference to the accompanying drawings, in which:

[0016] Figure 1 illustrates an example communication environment in which example embodiments of the present disclosure may be implemented;

[0017] Figure 2 illustrates a signaling diagram for authenticating a device according to some example embodiments of the present disclosure;

[0018] Figure 3 illustrates another signaling diagram for authenticating a device according to some example embodiments of the present disclosure;

[0019] Figure 4 A flowchart illustrating a method implemented at a first device according to some example embodiments of the present disclosure is shown;

[0020] Figure 5 A flowchart illustrating a method implemented at a second device according to some example embodiments of the present disclosure is shown;

[0021] Figure 6 A flowchart illustrating a method implemented at a third device according to some example embodiments of the present disclosure is shown;

[0022] Figure 7 illustrates a flow chart of a method implemented at a fourth device according to some example embodiments of the present disclosure;

[0023] Figure 8 A flowchart illustrating a method implemented at a fifth device according to some example embodiments of the present disclosure is shown;

[0024] Fig. 9 illustrates a simplified block diagram of a device suitable for implementing an example embodiment of the present disclosure; and

[0025] Fig.10 A block diagram of an example computer-readable medium according to some example embodiments of the present disclosure is illustrated.

[0026] Throughout the drawings, the same or similar reference numerals refer to the same or similar elements. DETAILED DESCRIPTION

[0027] The principles of the present disclosure will now be described with reference to some example embodiments. It should be understood that these embodiments are described only for illustrative purposes and help those skilled in the art to understand and implement the present disclosure, and do not represent any limitation on the scope of the present disclosure. The embodiments described herein can be implemented in various ways except for the way described below.

[0028] In the following description and claims, unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs.

[0029] In this disclosure, references to "one embodiment," "an embodiment," and "an example embodiment," etc. indicate that the described embodiment may include a particular feature, structure, or characteristic, but not every embodiment must include the particular feature, structure, or characteristic. Furthermore, such phrases do not necessarily refer to the same embodiment. Furthermore, when a particular feature, structure, or characteristic is described in conjunction with an embodiment, those skilled in the art believe that it is within the knowledge of those skilled in the art to affect such feature, structure, or characteristic in conjunction with other embodiments, whether or not explicitly described.

[0030] It should be understood that although the terms "first", "second", etc. can be used to describe various elements in this article, these elements should not be limited by these terms. These terms are only used to distinguish one element from another element. For example, without departing from the scope of the exemplary embodiment, the first element can be referred to as the second element, and similarly, the second element can be referred to as the first element. As used herein, the term "and / or" includes any and all combinations of one or more of the listed terms.

[0031] As used herein, unless explicitly stated, performing a step “in response to A” does not indicate that the step is performed immediately after “A” occurs, but may include one or more intermediate steps.

[0032] The terms used herein are for the purpose of describing specific embodiments only and are not intended to limit the exemplary embodiments. As used herein, the singular forms "a", "an", and "the" are also intended to include the plural forms, unless the context clearly indicates otherwise. It will also be understood that the terms "comprises", "comprising", "having", "having", "including", and / or "comprising" when used herein specify the presence of the features, elements, and / or components, etc., but do not exclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.

[0033] As used in this application, the term "circuitry" may refer to one or more or all of the following:

[0034] (a) hardware circuit implementation only (such as implementation in analog and / or digital circuitry only), and

[0035] (b) a combination of hardware circuitry and software such as (where applicable):

[0036] (i) a combination of analog and / or digital hardware circuits and software / firmware, and

[0037] (ii) any portion of a hardware processor(s) with software (including digital signal processor(s), software and memory(s) that work together to enable a device (such as a mobile phone or server) to perform various functions), and

[0038] (c) Hardware circuits and / or processor(s), such as microprocessor(s) or portions of microprocessor(s), that require software (e.g., firmware) to operate, but which may not be present when the software is not required for operation.

[0039] This definition of circuitry applies to all uses of the term in this application, including in any claims. As a further example, as used in this application, the term circuitry also covers an implementation of only a hardware circuit or processor (or multiple processors) or a portion of a hardware circuit or processor and its accompanying software and / or firmware. For example, if applicable to a particular claim element, the term circuitry also covers a baseband integrated circuit or processor integrated circuit for a mobile device, or a similar integrated circuit in a server, cellular network device, or other computing or network device.

[0040] As used herein, the term "communication network" refers to a network that follows any suitable communication standard, such as new radio (NR), long term evolution (LTE), advanced LTE (LTE-A), wideband code division multiple access (WCDMA), high speed packet access (HSPA), narrowband Internet of Things (NB-IoT), etc. In addition, the communication between the terminal equipment and the network equipment in the communication network can be performed according to any suitable generation of communication protocol, including but not limited to the first generation (1G), second generation (2G), 2.5G, 2.75G, third generation (3G), fourth generation (4G), 4.5G, fifth generation (5G) communication protocol, and / or any other protocol currently known or to be developed in the future. The embodiments of the present disclosure can be applied in various communication systems. Considering the rapid development of communication, there will certainly be communication technologies and systems of future types that can implement the present disclosure. It should not be considered that the scope of the present disclosure is limited to the above-mentioned system.

[0041] As used herein, the term "network device" refers to a node in a communication network, via which a terminal device accesses the network and receives services from the network. Depending on the terminology and technology applied, a network device may refer to a base station (BS) or an access point (AP), such as a node B (NodeB or NB), an evolved NodeB (eNodeB or eNB), a NR NB (also referred to as a gNB), a remote radio unit (RRU), a radio head (RH), a remote radio head (RRH), a relay, an integrated access and backhaul (IAB) node, a low-power node (such as a femto, a micro), a non-terrestrial network (NTN) or a non-grounded network device (such as a satellite network device, a low earth orbit (LEO) satellite, and a synchronous earth orbit (GEO) satellite), an aircraft network device, etc. In some example embodiments, a radio access network (RAN) split architecture includes a centralized unit (CU) and a distributed unit (DU) at an IAB host node. An IAB node includes a mobile terminal (IAB-MT) portion that behaves like a UE to a parent node, and a DU portion of the IAB node behaves like a base station to a next-hop IAB node.

[0042] The term "terminal device" refers to any terminal device capable of wireless communication. As an example and not limitation, the terminal device may also be referred to as a communication device, a user equipment (UE), a subscriber station (SS), a portable subscriber station, a mobile station (MS) or an access terminal (AT). The terminal device may include, but is not limited to, a mobile phone, a cellular phone, a smart phone, a voice over IP (VoIP) phone, a wireless local loop phone, a tablet computer, a wearable terminal device, a personal digital assistant (PDA), a portable computer, a desktop computer, an image capture terminal device (such as a digital camera), a game terminal device, a music storage and playback application, a vehicle-mounted wireless terminal device, a wireless endpoint, a mobile station, a laptop embedded device (LEE), a laptop mounted device (LME), a USB dongle, a smart device, a wireless customer premises equipment (CPE), an Internet of Things (IoT) device, a watch or other wearable device, a head mounted display (HMD), a vehicle, a drone, medical equipment and applications (e.g., remote surgery), industrial equipment and applications (e.g., robots and / or other wireless devices operating in industrial and / or automated processing chain environments), consumer electronic devices, equipment operating on commercial and / or industrial wireless networks, etc. The terminal device may also correspond to a mobile terminal (MT) part of an IAB node (eg, a relay node).In the following description, the terms "terminal device", "communication device", "terminal", "user equipment" and "UE" may be used interchangeably.

[0043] Example Environment

[0044] Figure 1 An example communication environment 100 in which an example embodiment of the present disclosure may be implemented is illustrated. In the communication environment 100, a terminal device 110 may access a communication network, such as a 5G core (5GC) network or any other suitable network. The communication environment 100 may support different types of access technologies, such as cellular access or non-cellular access.

[0045] The terminal device 110 can access the communication network via a non-cellular mechanism or non-cellular access. As used herein, a terminal device that accesses a communication network via a non-cellular mechanism can be referred to as a non-cellular device or a device with non-cellular access. Non-cellular access can include non-3GPP access. The terminal device 110 with non-3GPP access can use non-3GPP access technology to connect to the communication network, but does not support the non-access layer (NAS) on the non-3GPP access. Such a terminal device can be referred to as a non-3GPP device or a device with non-3GPP access. It should be understood that in some cases, the terminal device 110 can also support cellular access or 3GPP access. Unless explicitly stated, in some example embodiments, the terminal device 110 accesses the communication network via a non-cellular mechanism.

[0046] In some example embodiments, the non-3GPP device may include an authenticatable non-3GPP (AUN3) device. As used herein, the term "AUN3 device" may refer to a device that a communication network (such as a 5GC network) can authenticate or identify. An AUN3 device may not support NAS over non-3GPP access, but may have network credentials, such as 5G credentials or other suitable credentials. For example, a universal subscriber identity module (USIM) may exist for an AUN3 device, but a protocol stack or NAS may not exist for the AUN3 device. In some example embodiments, the AUN3 device may support a network authentication method, such as a 5GC authentication method. Alternatively or additionally, the AUN3 device may have a subscription to a network such as a 5GC network.

[0047] The terminal device 110 may access the communication network via a network device such as a residential gateway (RG) 120 (also referred to as a wireless local area network (WLAN) access point (AP)) or any other suitable network device. For example, the terminal device 110 may access the communication network by connecting to the RG 120 via a WLAN or a wired connection. The terminal device 110 or a non-3GPP device using a non-3GPP mechanism may connect to the RG 120 using a non-3GPP access technology, but does not support NAS on non-3GPP access.

[0048] The communication environment 100 includes a wired access gateway function (W-AGF) 130 connected to the RG 120. The RG 120 may be connected to the communication network via 3GPP access or via the W-AGF 130. The communication environment 100 may also include an access and mobility management function (AMF) 140 and a security anchor function (SEAF) 145 both connected to the W-AGF 130, an authentication server function (AUSF) 150 connected to the AMF 140 and the SEAF 145, and a unified data management (UDM) 160 connected to the AUSF 150.

[0049] AMF 140 may provide registration and connection management and other suitable functions. For example, AMF 140 may provide support for authentication of terminal device 110. SEAF 145 may also provide support for authentication of terminal device 110. AUSF 150 may provide authentication server functions and other suitable functions. UDM 160 may provide support for generation of authentication credentials, subscription management and other suitable functions.

[0050] It should be understood that Figure 1The number of devices and their connections shown are for illustrative purposes only and do not represent any limitation. The communication environment 100 may include any suitable number of devices for implementing the example embodiments of the present disclosure. Although not shown, it should be understood that one or more additional devices may be located in the communication environment 100, and one or more additional devices may be connected to the communication environment 100. It should be understood that in some example embodiments, the communication environment 100 may include more or fewer devices or apparatuses. For example, the communication environment 100 may not include the AMF 140 or the SEAF 145.

[0051] It should also be understood that the exemplary communication environment 100 is shown for illustrative purposes only and does not represent any limitation on the scope of the present disclosure. The embodiments of the present disclosure may also be applied to communication environments with different structures.

[0052] The communication in the communication environment 100 can be implemented according to any appropriate (multiple) communication protocols, including but not limited to cellular communication protocols of the first generation (1G), second generation (2G), third generation (3G), fourth generation (4G), fifth generation (5G), sixth generation (6G), etc., wireless local area network communication protocols (such as Institute of Electrical and Electronics Engineers (IEEE) 802.11, etc.), and / or any other protocol currently known or to be developed in the future. In addition, the communication can utilize any appropriate wireless communication technology, including but not limited to: code division multiple access (CDMA), frequency division multiple access (FDMA), time division multiple access (TDMA), frequency division duplex (FDD), time division duplex (TDD), multiple input multiple output (MIMO), orthogonal frequency division multiplexing (OFDM), discrete Fourier transform spread spectrum OFDM (DFT-s-OFDM) and / or any other technology currently known or to be developed in the future.

[0053] As described above, the terminal device may be connected to the communication network via a non-cellular mechanism (such as a non-3GPP access mechanism). In order to ensure the security of data communications of such a terminal device, an authentication or registration process needs to be performed for the terminal device.

[0054] In some solutions, it has been proposed to provide differentiated services (such as quality of service or billing) for various types of non-3GPP devices and terminal devices connected behind 5G RG. In some other solutions, it has been proposed to authenticate non-5G capable (N5GC) devices. However, such N5GC authentication process only considers wired devices connected to RG using Ethernet, and cannot cover non-3GPP devices, such as AUN3 devices. Authentication or authorization of non-3GPP devices has not yet been resolved.

[0055] How communication signaling works and examples

[0056] As described above, authenticating devices with non-cellular access is challenging. According to an exemplary embodiment of the present disclosure, a solution for authentication of devices with non-cellular access is provided. In the solution, a first device sends a registration request for a third device to a second device. The registration request indicates that the third device is accessing a network via a non-cellular mechanism. That is, the registration request indicates that the third device is a device with non-cellular access. The first device receives a message from the second device indicating that the third device is authenticated. After receiving the message, the first device sends security information to a fourth device for establishing a connection between the third device and the fourth device.

[0057] In this way, the third device can be authenticated. A secure connection between the third device and the network can be established. Security for both the third device and the network can be ensured.

[0058] Hereinafter, exemplary embodiments of the present disclosure will be described in detail with reference to the accompanying drawings.

[0059] Figure 2 A signaling diagram 200 for authenticating a device according to some example embodiments of the present disclosure is shown. Figure 2 As shown, signaling diagram 200 involves a first device 201, a second device 202, a third device 203, a fourth device 204, a fifth device 205, and a sixth device 206. In some example embodiments, first device 201 may be Figure 1 In the W-AGF 130, the second device 202 may be Figure 1 In the AMF 140 or SEAF 145, the third device 203 may be Figure 1 In the terminal device 110, the fourth device 204 may be Figure 1 In the RG 120, the fifth device 205 may be Figure 1 In the AUSF 150, the sixth device 206 may be Figure 1 UDM 160 in.

[0060] although Figure 2 A first device 201, a second device 202, a third device 203, a fourth device 204, a fifth device 205 and a sixth device 206 are illustrated in the figure, but it can be understood that there can be multiple devices performing similar operations as described below with respect to the first device 201, the second device 202, the third device 203, the fourth device 204, the fifth device 205 or the sixth device 206.

[0061] In operation, a connection may be established (210) between the third device 203 and the fourth device 204. For example, a WEAN connection may be established (210) between the third device 203 and a WLAN access network (AN) using IEEE 802.11 or other suitable procedures. For another example, a wired connection may be established (210) between the third device 203 and the fourth device 204.

[0062] In some example embodiments, an identification retrieval process 213 may be performed between the third device 203, the fourth device 204, and the first device 201. For example, a message with an identification of the third device 203 (referred to as an identification message) may be sent to the fourth device 204 and the first device 201. Alternatively, in some example embodiments, an identification message with an identification of the third device 203 may be sent by the third device 203 to the fourth device 204. The fourth device 204 may forward the identification message to the first device 201.

[0063] The identification message or the identification of the third device 203 may at least indicate that the third device 203 is accessing the network via a non-cellular mechanism. For example, the identification of the third device 203 may indicate a device type of the third device 203. The device type indicates an associated access type of the non-cellular mechanism used by the third device 203. That is, the device type may indicate a non-cellular mechanism.

[0064] The device type may include a non-cellular device type, a non-3GPP device type, an AUN3 device type, or any other suitable type. For example, the device type of the non-cellular type of the third device 203 may indicate that the access type of the third device 203 is a non-cellular access. In other words, the non-cellular access type is associated with a non-cellular mechanism. That is, the third device 203 is accessing the network via a non-cellular mechanism.

[0065] Similarly, the non-3GPP type or AUN3 type device type of the third device 203 may indicate that the access type of the third device 203 is a non-3GPP access without NAS. In other words, the non-3GPP access without NAS type is associated with a non-3GPP without NAS mechanism. That is, the third device 203 is accessing the network via a non-3GPP mechanism without NAS.

[0066] In some example embodiments, the identification of the third device 203 may be in a network access identifier (NAI) format, such as "username@realm". In other words, the identification message may include the NAI of the third device 203 in the form of "username@realm". It should be understood that the above example names in the NAI format are only for illustration purposes and do not represent any limitation. Any other suitable format may also be applied.

[0067] In some example embodiments, the identification message of the third device may further include an identification of the third device 203, such as a subscription permanent identifier (SUPI) of the third device 203. Alternatively, the identification of the third device 203 may include a subscription hidden identifier (SUCI), an identifier in a NAI format (such as a SUCI in a NAI format), or an identifier in a globally unique temporary identifier (such as a 5G-GUTI).

[0068] Alternatively or additionally, in some example embodiments, a layer 2 (L2) connection between the third device 203, the fourth device 204, and the first device 201 may be established. The L2 connection or L2 data link may support extensible authentication protocol (EAP) encapsulation. The EAP identity retrieval process may be performed via the L2 connection. For example, the first device 201 may send an EAP identity request to the third device 203. Based on the receipt of the EAP identity request, the third device 203 may send an EAP response or EAP message with its identity to the first device 201 and the fourth device 204. The EAP request, EAP response, or EAP message (such as EAP over link (EAPOL)) may be encapsulated within an L2 frame. The example messages, requests, or responses (such as EAPOL) described below may also be encapsulated within an L2 frame. It should be understood that the identity retrieval process 213 with EAP requests and responses is for illustrative purposes only and does not represent any limitation. Any suitable identity retrieval process 213 may be applied.

[0069] Based on the identification of the third device 203, the first device 201 can generate (216) a registration request for the third device 203. For example, the first device 201 can generate (216) a registration request on behalf of the third device 203 based on the received identification message. The generated registration request at least indicates that the third device 203 is accessing the network via a non-cellular mechanism.

[0070] By indicating the non-cellular mechanism in the registration request, non-cellular devices such as AUN3 devices can be identified by other devices. In this way, other devices can distinguish non-cellular devices from other devices such as 3GPP devices. Therefore, other devices can implement authentication requirements for devices such as AUN3 devices.

[0071] In some example embodiments, the registration request may include an indication of a requirement for an encryption key for the third device 203. Alternatively or additionally, the registration request may include an indication of the device type of the third device 203. For example, the indication of the requirement for an encryption key may include a flag indicating an encryption requirement for an AUN3 device. The flag may indicate that the third device 203 is an AUN3 device (i.e., the third device 203 is accessing the network via a non-3GPP mechanism without NAS) and that the encryption requirement indication for the third device is true. The flag may also indicate that the registration request is on behalf of an AUN3 device and that protection is required for the interface between the AUN3 device (which is the third device 203) and the fourth device 204. In other words, the flag may indicate that the AUN3 device is requesting encryption information or security information.

[0072] The indication of the device type may include an explicit indication, such as an "AUN3 device" field, etc. The indication of the device type may be in NAI format. For example, the indication may be a NAI with "AUN3" information, such as "<5G_device_unique_identity>@nai.aun3.5gc-nn.mnc <mnc>.mcc <mcc>.3gppnetwork.org”、"<5G_device_unique_identity>@5gc.aun3.mnc <mnc>.mcc <mcc>.3gppnetwork.org” etc. The indication of the device type may indicate that the third device 203 is an AUN3 device. That is, an AUN3 device that accesses the network via a non-3GPP mechanism without NAS is requesting registration.

[0073] Alternatively or additionally, in some example embodiments, the registration request may indicate an identity of the third device 203. For example, in an example where the received identity of the third device includes an identity such as a SUPI of the third device 203, the registration request may include a SUCI of the third device 203. The SUCI may be generated by the first device 201 using a NULL scheme based on the SUPI.

[0074] In some example embodiments, the registration request may also include a wired network name, such as a service network name (SN name), if available. An example registration request may include a registration request (SUCI, SN name, flag indicating encryption requirement for AUN3 devices). It should be understood that the above examples are for illustration purposes only and do not represent any limitation. Any other suitable information may be included in the registration request.

[0075] In some example embodiments, the first device 201 may perform additional actions, such as selecting the second device 202. For example, the first device 201 may select Figure 1 The AMF 140 or the SEAF 145 in the first device 201 is used as the second device 202. The first device 201 can select the second device 202 using any suitable method.

[0076] The first device 201 sends (219) a registration request for the third device 203 to the second device 202. The second device 202 receives (222) the registration request. The second device 202 sends (225) a first authentication request for the third device 203 to the fifth device 205. The first authentication request at least indicates that the third device is accessing the network via a non-cellular mechanism. The first authentication request may also include other information, such as an identification of the third device 203 or other information included in the registration request.

[0077] In the example where the registration request includes Registration Request (SUCI, SN name, flag indicating the encryption requirement for AUN3 device), an example of the first authentication request may include: Nausf_UEAuthentication_AuthenticateRequest (SUCI, SN name, flag indicating the encryption requirement for AUN3 device). It should be understood that the above example of the first authentication request is for illustrative purposes only and does not represent any limitation.

[0078] The fifth device 205 receives (228) the first authentication request. The fifth device 205 sends (231) a second authentication request for the third device 203 to the sixth device 206. The second authentication may be similar to the first authentication. In some example embodiments, the content in the first authentication request and the second authentication request may be the same. Alternatively, the second authentication may not indicate a non-cellular mechanism used by the third device 203.

[0079] In some example embodiments, the second authentication request may indicate that the third device 203 requires a session key. In the example where the first authentication request includes Nausf_UEAuthentication_AuthenticateRequest (SUCI, SN name, flag indicating encryption requirement for AUN3 device), the second authentication request may include Nudm_UEAuthentication_AuthenticateRequest (SUCI, SN name, optional flag indicating encryption requirement for AUN3 device).

[0080] It should be understood that the above examples of the first authentication request and the second authentication request are only for illustrative purposes and do not represent any limitation. Any other suitable authentication request may be applied.

[0081] The sixth device 206 receives (234) a second authentication request for the third device 203 from the fifth device 205. In some example embodiments, the sixth device 206 may initiate an authentication process 237 for the third device 203. For example, the sixth device 206 may perform de-hiding for the SUCI included in the second authentication request to obtain the SUPI for the third device 203. In addition, the sixth device 206 may perform authentication selection, such as selecting an authentication process 237 based on the second authentication request. The sixth device 206 may initiate the selected authentication process 237. The sixth device may use any suitable selection method. The scope of the present disclosure is not limited in this regard.

[0082] In some example embodiments, the authentication process 237 may include an EAP-Transport Level Security (EAP-TLS) authentication process, or also referred to as an authentication process for EAP-TLS 237. Any suitable EAP-TLS authentication process may be applied. Alternatively or additionally, other authentication processes may also be applied, which will be described below.

[0083] Taking the EAP-TLS authentication process as an example, if the authentication process is successful, the fifth device 205 may determine that the third device 203 is authenticated based on the authentication process 237 initiated by the sixth device 206. In such a scenario, the fifth device 205 may send (243) an authentication response to the second device 202. In some example embodiments, the authentication response may indicate that the third device 203 is authenticated.

[0084] Alternatively or additionally, the authentication response may include security information for the third device 203. In the example where the authentication response includes security information, the fifth device 205 may generate (240) the security information based on credentials for the third device 203, such as EAP credentials for the AUN3 device.

[0085] In some example embodiments, the security information may include a session key for the third device, such as a master session key (MSK), an extended master session key (EMSK), etc. It should be understood that although the generation of security information (240) is shown as after the authentication process 237, in some example embodiments, the security information generation may be performed before the authentication process 237, or during the authentication process 237.

[0086] An example authentication response including security information may include Nausf_UEAuthentication_AuthenticateResponse (EAP Success, EMSK). It should be understood that the above example authentication response is for illustration purposes only and does not represent any limitation. Any other suitable authentication response may be applied.

[0087] The second device 202 may receive (246) the authentication response. The second device 202 sends (249) to the first device 201 a first message indicating that the third device 203 is authenticated. For example, the second device 202 may send (249) the first message based on receipt of the authentication response. Alternatively, in some example embodiments, the second device may send (249) the first message under other conditions. The first device 201 receives (252) the first message.

[0088] In an example where the authentication response includes security information for the third device 203, the first message may include the security information. In an example where the authentication response includes Nausf_UEAuthentication_AuthenticateResponse (EAP success, EMSK), the first message may include Authentication_Result (EAP success, EMSK). It should be understood that the above example first message is for illustration purposes only and does not represent any limitation. Any other suitable first message may be applied.

[0089] The first device 201 sends (255) security information for the third device 203 to the fourth device 204 to establish a connection between the third device 203 and the fourth device 204. In this case, the fourth device receives (258) the security information. Examples of security information have been described above and will not be repeated here.

[0090] In some example embodiments, the first device 201 may send (261) a second message indicating that the third device 202 is authenticated to the third device 203. For example, the first device 201 may send (261) an EAP success message to the third device 203 via the L2 connection. The third device 203 may receive (264) the second message.

[0091] The third device 203 may generate (267) a key for communicating with the fourth device. Similarly, the fourth device 204 may generate (270) the same key for communicating with the third device 203. For example, the key may include a WLAN key. In some example embodiments, the third device 203 may generate (267) a key such as a WLAN key based on credentials for the third device 203. For example, based on receipt of the second message (264), the third device 203 may generate (267) a key such as a WLAN key based on the credentials. In some example embodiments, the fourth device 204 may generate (270) a key such as a WLAN key based on the received (258) security information.

[0092] In some solutions, it is proposed to use the slice information of the network node to establish a connection between the terminal device and the network node. However, such a solution will open the slice information of the network node to the terminal device. This will pose a security threat to the network or the company that owns the slice. How to select a trusted non-3GPP gateway function (TNGF) or non-3GPP interworking function (N3IWF) that supports the single network slice selection auxiliary information ((multiple) S-NASSAI) requested by the terminal device during authentication or registration via a non-3GPP access network remains a concern.

[0093] In some exemplary embodiments according to the present disclosure, the third device 203 and the fourth device 204 perform a process of establishing a connection with each other based on the above security information. Details on establishing a connection may be described below.

[0094] In some example embodiments, the third device 203 and the fourth device 204 perform a process of establishing a connection based on security information with each other. The process may include a handshake process 273. For example, the third device 203 and the fourth device 204 may perform a handshake process 273 using security information such as EMSK. The handshake process 273 may include a 4-way handshake process. By performing the handshake process 273, the third device may establish a secure connection with the WLAN AP (e.g., RG).

[0095] By using the current connection establishment process shown in signaling diagram 200, the slice information of the network node may not be used for authentication of a device with non-cellular access. For example, a third device may use the security information to generate a WLAN key for establishing a connection. The security information may be generated based on credentials for the third device. Thus, the slice information of the network node may be protected. The network and the peer that owns the slice will be protected.

[0096] Already referenced Figure 2 Example embodiments are described regarding authentication for devices using non-cellular mechanisms. Through such authentication for devices, devices with non-cellular access, such as AUN3 devices behind RGs connected to a network, can be identified, authorized, and authenticated. In this way, a secure connection can be established, thereby protecting communication security.

[0097] exist Figure 2 In the example of , the EAP-TES authentication process is used as an example of the authentication process. Alternatively or additionally, other types of authentication processes may be applied.

[0098] Figure 3 Another signaling diagram 300 for authenticating a device according to some example embodiments of the present disclosure is illustrated. In the signaling diagram 300, the Figure 2 The authentication process 237 in FIG. 1 is different from the authentication process 310 in FIG. 1 , which will be described below. Figure 3 As shown, similar to the signaling diagram 200 , the signaling diagram 300 involves a first device 201 , a second device 202 , a third device 203 , a fourth device 204 , a fifth device 205 , and a sixth device 206 .

[0099] In some example embodiments, the first device 201 may be Figure 1 In W-AGF130, the second device 202 may be Figure 1 In the AMF 140 or SEAF 145, the third device 203 may be Figure 1 In the terminal device 110, the fourth device 204 may be Figure 1 In the RG 120, the fifth device 205 may be Figure 1 In the AUSF 150, the sixth device 206 may be Figure 1 The UDM160 in the.

[0100] although Figure 3 A first device 201, a second device 202, a third device 203, a fourth device 204, a fifth device 205 and a sixth device 206 are illustrated in the figure, but it should be understood that there may be multiple devices that perform similar operations as described below with respect to the first device 201, the second device 202, the third device 203, the fourth device 204, the fifth device 205 or the sixth device 206.

[0101] In operation, the devices involved in the signaling diagram may perform similar processes or actions before the authentication process 310 for the third device 203. For the purpose of illustration, those similar processes or actions illustrated with the same reference numerals will not be repeated here. In the signaling diagram 300, the sixth device 206 may select an authentication process 310 different from the authentication process 237. The sixth device 206 may initiate the authentication process 310.

[0102] In some example embodiments, authentication process 310 may include an Extensible Authentication Protocol Authentication and Key Agreement (EAP-AKA) process, an Improved EAP-AKA (EAP-AKA') process, or a 5G Authentication and Key Agreement (5G AKA) process. Any suitable EAP-AKA, EAP-AKA', or 5G AKA process may be applied.

[0103] In some example embodiments, the second device 202 may generate (313) a first key for the first device 201. For example, the second device 202 may generate (313) an access type associated with a non-cellular mechanism used by the third device 203 based at least in part. In some example embodiments, the second device 202 may obtain an access type associated with the third device 203 based on the received (222) registration request. In some example embodiments, the second device 202 may generate (313) a first key for the first device 201. For example, the second device 202 may generate (313) an access type associated with the non-cellular mechanism used by the third device 203 based at least in part. AMF ) and the associated access type of the third device 203 to generate (313) a first key (referred to as K WAGF' ).

[0104] In some example embodiments, the second device 202 may generate (313) a first key K using a key derivation function (KDF). WAGF' The second device 202 may input the following parameters in the input S to the KDF:

[0105] FC=0x6E or 0x<will be defined>;

[0106] Pl = access type specifier;

[0107] LI = length of the access type specifier (ie, 0x00, 0x01).

[0108] In some example embodiments, the values ​​of the access type discriminator for different apparatuses may be determined based on a predetermined table (eg, Table 1 below).

[0109] Table 1: Example access type specifiers

[0110] Access type specifier value 3GPP 0x01 Non-3GPP access 0x02 Non-3GPP access without NAS 0x03

[0111] For example, in the example of the third device 203 (eg, non-3GPP device) indicating the associated access type of non-3GPP access, when deriving K WAGF' When the access type discriminator is set to a value for "non-3GPP access", in the example of the third apparatus 203 (eg, AUN3 device) indicating the associated access type of non-3GPP access without NAS, when deriving K WAGF' When the access type specifier is set to the value of "non-3GPP access without NAS", for example 0x03.

[0112] It should be understood that the above parameters and their corresponding values ​​for generating (313) the first key are for illustration purposes only and do not represent any limitation. Any suitable method for determining the device key may be applied. For example, an additional parameter L0 representing the length of the device discriminator having a value (e.g., 0x00, 0x04, etc.) may be applied. In addition, an additional parameter P0 representing the device discriminator may be applied (for AUN3 devices, it may be set to 0x01, otherwise it will be set to 0x00).

[0113] The second device 202 sends (316) a first message to the first device 201 indicating that the third device 203 is authenticated. For example, the second device 202 may determine that the authentication process 310 for the third device 203 is successful. Based on the determination of the successful authentication of the third device 203, the second device 202 sends (316) a first message to the first device. The first message may include an authentication success message (such as an EAP success message) indicating the successful authentication of the third device. For example, the first message may be in a NAS security mode command mode with a null security algorithm, such as an N2 message NAS security mode command (null security algorithm, [EAP success]). It should be understood that the example of the first message is for illustrative purposes only and does not represent any limitation. Any suitable first message may be applied.

[0114] The first device 201 receives (319) the first message. The first device 201 may store (322) the first message, or alternatively store an EAP success message included in the first message.

[0115] In some example embodiments, the first device 201 may send (325) a second message indicating completion of the security mode to the second device 202. For example, based on the reception of the first message (319), or alternatively based on the storage of the first message (322), the first device 201 may send (325) the second message. An example of the second message may include an N2 message NAS Security Mode Complete. It should be understood that the example of the second message is for illustration purposes only and does not represent any limitation. Any suitable second message may be applied.

[0116] In some example embodiments, the second device 202 may receive (328) the second message. Based on receipt of the second message, the second device 202 may send (331) the first key to the first device 201. The first key may be generated (313) by the second device 202. For example, the second device 202 may send an N2 Initial Ctx Establishment Request or a N2 Initial Ctx Establishment Request with the first key K to the first device 201. WAGF' Other appropriate information.

[0117] In some example embodiments, the first device 201 may receive (334) a signal such as K WAGF' The first device 201 may be based on a first key such as K WAGF' The first key generates (337) security information for the third device 203. For example, the security information may include a key for the third device 203, such as a pairwise master key (PMK) for the third device 203.

[0118] In some example embodiments, the first device 201 may use a KDF based on the first key K WAGF' to generate (337) a PMK (referred to as K AUN3 ). For example, the first device 201 may input the following parameters in the input S to the KDF:

[0119] FC = 0x <will be defined>;

[0120] P0 = usage type specifier (i.e., 0x01);

[0121] L0 = length of the used type specifier (ie, 0x00, 0x01).

[0122] It should be understood that the above parameters and their corresponding values ​​used to generate (337) security information (such as PMK) are for illustration purposes only and do not represent any limitation.Any suitable method for determining a device key may be applied.

[0123] The first device 201 sends (340) security information, such as a PMK, to the fourth device 204, the security information being used to establish a connection between the third device 203 and the fourth device 204. Based on the reception (319) of the first message, the first device 201 sends (340) the security information. For example, based on the reception (319) of the first message, the first device 201 may receive (334) a first key from the second device 202, generate (337) security information based on the first key, and send (340) the security information. In some example embodiments, the first device 201 may send an authentication success message, such as an EAP success message, and the security information to the fourth device 204. For example, the first device 201 may send (EAP success, PMK) to the fourth device 204.

[0124] The fourth device 204 receives (343) security information from the first device 201. In some example embodiments, the fourth device 204 may also receive an authentication success message such as an EAP success message and the security information from the first device 201. For example, the fourth device 204 may receive, for example, (EAP success, PMK) from the first device 201.

[0125] In some example embodiments, the fourth device 204 may send (346) an authentication success message, such as an EAP success message, to the third device 203. The third device 203 may receive (349) the authentication success message, such as an EAP notification or an (EAP success) message.

[0126] In some example embodiments, the third device 203 may generate (352) a key for communicating with the fourth device. Likewise, the fourth device 204 may generate (355) the same key for communicating with the third device 203. For example, the same key may include a WLAN key.

[0127] In some example embodiments, the third device 203 may generate (352) a key, such as a WLAN key, based on the associated access type of the third device 203. For example, the third device 203 may generate a PMK (or K) based on the associated access type of the third device 203 (e.g., non-3GPP access without NAS). AUN3 ). The third device may use the same KDF to generate the PMK. How to use the KDF to generate the PMK has been described above and will not be repeated here.

[0128] The third device 203 may generate (352) a WLAN key based on the PMK. In some example embodiments, the fourth device 204 may generate (343) a WLAN key based on the received PMK (or K AUN3 ) and other security information to generate (355) keys such as WLAN keys.

[0129] The third device 203 and the fourth device 204 perform a process of establishing a connection with each other based on the security information. The process may include a handshake process 358. For example, the third device 203 and the fourth device 204 may perform the handshake process 358 using security information such as PMK. The handshake process 358 may include a 4-way handshake. By performing the handshake process 358, the third device 203 (e.g., AUN3 device) can establish a secure connection with the WLAN AP (e.g., RG).

[0130] In some example embodiments, a secure connection 361 may be established between the third device 203 and the fourth device 204. The secure connection may include an L2 connection or a layer 3 (L3) connection. Alternatively or additionally, the first device 201 may send (364) an N2 Initial Ctx Setup Response to the second device 202. For example, the N2 Initial Ctx Setup Response may correspond to an N2 Initial Ctx Setup Request received from the second device 202 using the first key. The second device 202 may receive (367) the N2 Initial Ctx Setup Response.

[0131] Already referenced Figure 3 Example embodiments are described regarding authentication for devices with non-cellular access. Figure 3 In the example of FIG. 1 , the EAP-AKA authentication process is used as an example of the authentication process. Through such authentication for devices with non-cellular access, devices with non-cellular access, such as AUN3 devices behind the RG connected to the network, can be identified, authorized, and authenticated. In this way, a secure connection can be established, thereby protecting communication security.

[0132] In addition, by using the current connection establishment process shown in signaling diagram 300, the slice information of the network node may not be used for authentication of devices with non-cellular access. For example, the third device may use the security information to generate a WEAN key for establishing a connection. The security information may be generated based on the associated access type of the third device. Therefore, the slice information of the network node may be protected. The network and the peers that own the slice will be protected.

[0133] It should be understood that authentication process 237 and authentication process 310 are shown for illustrative purposes only and do not represent any limitation on the scope. Any suitable authentication process may be applied to the authentication of the third device. It should also be understood that Figure 2 The signaling diagram 200 and Figure 3 The signaling diagram 300 in FIG. 2 is shown for illustration purposes only and does not represent any limitation. The signaling diagram 200 or the signaling diagram 300 may include additional processes or actions not shown, and / or may omit some of the processes or actions shown, and the scope of the present disclosure is not limited in this regard.

[0134] Example Method

[0135] Figure 4 4 is a flowchart of an example method 400 implemented at a first device according to some example embodiments of the present disclosure. In some example embodiments, the first device may include a network device such as Figure 2 The first device 201 or Figure 1 For the purpose of this discussion, we will start with Figure 2 The method 400 is described from the perspective of the first device 201 in FIG.

[0136] At block 410, the first device 201 sends a registration request for the third device 203 to the second device 202. The registration request at least indicates that the third device 203 is accessing the network via a non-cellular mechanism. For example, the registration request may include an indication of a requirement for an encryption key for the third device 203. Alternatively or additionally, the registration request may include an indication of a device type of the third device 203.

[0137] At block 420, the first device 201 receives a first message from the second device 202 indicating that the third device 203 is authenticated. In some example embodiments, the first message may also include security information. For example, the security information may include a session key for the third device 203, such as a master session key, or an extended master session key.

[0138] At block 430 , based on the receipt of the first message, the first device 201 sends security information for establishing a connection between the third device 203 and the fourth device 204 to the fourth device 204 .

[0139] In some example embodiments, the first message may also include a request for a security mode. In this case, based on the reception of the first message, the first device 201 may send a second message indicating the completion of the security mode to the second device 202. The first device 201 may receive a first key for the first device 201 from the second device 202. The first key may be determined by the second device 202 based on an access type associated with a non-cellular mechanism. The first device 201 may generate security information based on the first key. For example, the security information may include a pairwise master key for the third device 203.

[0140] In some example embodiments, the first device 202 may receive a third message from the third device 203 or the fourth device 204, the third message at least indicating that the third device 203 is accessing the network via a non-cellular mechanism. In addition, the first device 202 may generate a registration request based on the third message.

[0141] In some example embodiments, the third message and the registration request may also respectively indicate an identifier of the third device 203. For example, the identifier of the third device 203 may include at least one of the following items: a subscription hidden identifier, an identifier in a network access identifier format, or an identifier in a globally unique temporary identifier format.

[0142] In some example embodiments, the first device 201 may include a wired access gateway function, the second device 202 may include an access and mobility management function or a security anchor function, the third device 203 may include a certifiable non-3rd Generation Partnership Project device, and the fourth device 204 may include a residential gateway.

[0143] Figure 5 1 is a flowchart of an example method 500 implemented at a second device according to some example embodiments of the present disclosure. In some example embodiments, the second device may include a network device such as Figure 1 AMF 140 or SEAF 145 or Figure 2 For the purpose of discussion, we will start with Figure 2 The method 500 is described from the perspective of the second device 202 in FIG.

[0144] At block 510, the second device 202 receives a registration request for the third device 203 from the first device 201. The registration request at least indicates that the third device 203 is accessing a network via a non-cellular mechanism. For example, the registration request may include an indication of a requirement for an encryption key for the third device 203. Alternatively or additionally, the registration request may include an indication of a device type of the third device 203.

[0145] At block 520, the second device 202 sends an authentication request for the third device to the fifth device 205. The authentication request at least indicates that the third device is accessing the network via a non-cellular mechanism.

[0146] At block 530, the second device 202 sends a first message to the first device 201 indicating that the third device 203 is authenticated. In some example embodiments, at block 530, the second device 202 may determine that the authentication process for the third device 203 is successful. Based on the determination that the authentication process is successful, the second device 202 sends the first message.

[0147] In some example embodiments, the second device 202 also receives an authentication response to the authentication request from the fifth device 205. The authentication response may indicate that the third device is authenticated. The authentication response may include security information for the third device 203. In this case, the first message may also include security information.

[0148] Alternatively or additionally, the first message may also include a request for a security mode. In this case, the second device 202 may also generate a first key for the first device based on an access type associated with a non-cellular mechanism. The second device 202 may also receive a second message indicating completion of the security mode from the first device 202. Based on receipt of the second message, the second device 202 may also send the first key to the first device 201.

[0149] In some example embodiments, the first device 201 may include a wired access gateway functionality, the second device 202 may include an access and mobility management functionality or a security anchor functionality, the third device 203 may include an authenticatable non-3rd Generation Partnership Project device, and the fifth device 205 may include an authentication server functionality.

[0150] Figure 6 FIG. 6 is a flowchart showing an example method 600 implemented at a third device according to some example embodiments of the present disclosure. For example, the third device may include a terminal device such as Figure 1 The terminal device 110 or Figure 2 For the purpose of discussion, we will start with Figure 2 The method 600 is described from the perspective of the third device 203 in FIG.

[0151] At block 610, the third device 203 sends a message to at least one of the first device 201 or the fourth device 204, the message at least indicating that the third device 203 is accessing the network via a non-cellular mechanism. For example, the third device 203 may send the message to the first device 201. Alternatively or additionally, the third device 203 may send the message to the fourth device 204. In some example embodiments, the message may also indicate an identification of the third device 203. For example, the identification of the third device may include at least one of the following: a subscription hidden identifier, an identifier in a network access identifier format, or an identifier in a globally unique temporary identifier format.

[0152] At block 620, the third device 203 determines security information for establishing a connection between the third device 203 and the fourth device 204. For example, the third device 203 may determine the security information based on credentials for the third device 203. Alternatively or additionally, in some example embodiments, the third device 203 may determine the security information based at least in part on an access type associated with a non-cellular mechanism.

[0153] In some example embodiments, the security information may include one of the following: a session key for the third device, or a pairwise master key for the third device. For example, the session key may include one of the following: a master session key, or an extended master session key.

[0154] At block 630 , the third device 203 performs a process with the fourth device 204 based on the security information to establish a connection.

[0155] In some example embodiments, the third device 203 may also generate a key for communicating with the fourth device 204 based on the security information.

[0156] In some example embodiments, the third apparatus 203 may include a certifiable non-3rd Generation Partnership Project device, and the fourth apparatus may include a residential gateway.

[0157] Figure 7 FIG. 7 is a flowchart showing an example method 700 implemented at a fourth device according to some example embodiments of the present disclosure. For example, the fourth device may include a network device such as Figure 1 RG 120 or Figure 2 For the purpose of discussion, we will start with Figure 2 The method 700 is described from the perspective of the fourth device 204 in FIG.

[0158] At block 710 , the fourth device 204 receives security information for establishing a connection between the third device 203 and the fourth device 204 from the first device 201 .

[0159] At block 720 , the fourth device 104 performs a process with the third device 203 based on the security information to establish a connection.

[0160] In some example embodiments, the fourth device 204 may also generate a key for communicating with the third device 203 based on the security information.

[0161] In some example embodiments, the fourth device 204 may also receive a first message from the third device 203, the first message at least indicating that the third device 203 is accessing the network via a non-cellular mechanism. Based on the reception of the first message, the fourth device 204 may send a second message to the first device 201, the second message at least indicating that the third device 203 is accessing the network via a non-cellular mechanism.

[0162] In some example embodiments, the first device 201 may include a wired access gateway function, the third device 203 may include a certifiable non-3rd Generation Partnership Project device, and the fourth device 204 may include a residential gateway.

[0163] Figure 8 FIG. 8 is a flowchart of an example method 800 implemented at a fifth device according to some example embodiments of the present disclosure. In some example embodiments, the fifth device may include a network device such as Figure 1 AUSF 150 or Figure 2 For the purpose of discussion, we will start with Figure 2 Method 800 is described from the perspective of the fifth device 205 in FIG.

[0164] At block 810, the fifth device 205 receives a first authentication request for the third device 203 from the second device 202. The first authentication request at least indicates that the third device 203 is accessing a network via a non-cellular mechanism.

[0165] At block 820, the fifth device 205 sends a second authentication request for the third device 203 to the sixth device 206. In some example embodiments, the second authentication request may indicate that the third device 203 is accessing the network via a non-cellular mechanism.

[0166] In some example embodiments, the fifth device 205 also generates security information for the third device 203 based on the credentials for the third device 203. The fifth device 205 may determine that the third device 203 is authenticated based on the authentication process initiated by the sixth device 206. Based on the determination that the third device 203 is authenticated, the fifth device 205 may send an authentication response to the second device 202, the authentication response indicating that the third device 203 is authenticated and including the security information.

[0167] In some example embodiments, the security information may include a session key for the third device 203. For example, the session key may include one of the following: a master session key, or an extended master session key.

[0168] In some example embodiments, the authentication process may include one of: an Extensible Authentication Protocol Transport Level Security process, an Extensible Authentication Protocol Authentication and Key Agreement process, or a Fifth Generation Mobile Communication Technology Authentication and Key Agreement process.

[0169] In some example embodiments, the second device 202 may include access and mobility management functionality or security anchor functionality, the third device 203 may include an authenticatable non-3rd Generation Partnership Project device, the fifth device 205 may include authentication server functionality, and the sixth device 206 may include unified data management.

[0170] It should be understood that method 400 , method 500 , method 600 , method 700 , or method 800 may include additional blocks not shown, and / or may omit some of the shown blocks, and the scope of the present disclosure is not limited in this regard.

[0171] Example devices, equipment, and media

[0172] In some example embodiments, a first device (eg, Figure 2 The first device 201 in the method 400 may include a component for performing the corresponding operation of the method 400. The component may be implemented in any suitable form. For example, the component may be implemented as a circuit system or a software module. The first device may be implemented as Figure 2 The first device 201 or is included in Figure 2 In the first device 201.

[0173] In some example embodiments, a first device includes: a component for sending a registration request for a third device to a second device, the registration request at least indicating that the third device is accessing a network via a non-cellular mechanism; a component for receiving a first message from the second device indicating that the third device is authenticated; and a component for sending security information for establishing a connection between the third device and the fourth device to a fourth device based on receipt of the first message.

[0174] In some example embodiments, the registration request may include an indication of a requirement for an encryption key for the third apparatus.Alternatively or additionally, the registration request may include an indication of a device type of the third apparatus.

[0175] In some example embodiments, the first message may further include security information. For example, the security information may include a session key for the third device, such as at least one of the following: a master session key, or an extended master session key.

[0176] In some example embodiments, the first message may also include a request for a security mode. In this case, the first device may also include: a component for sending a second message indicating completion of the security mode to the second device based on the reception of the first message; a component for receiving a first key for the first device from the second device, the first key being determined by the second device based on an access type associated with a non-cellular mechanism; and a component for generating security information based on the first key. For example, the security information may include a pairwise master key for a third device.

[0177] In some example embodiments, the first device may further include a component for receiving a third message from a third device or a fourth device, the third message at least indicating that the third device is accessing the network via a non-cellular mechanism. In addition, the first device may further include a component for generating a registration request based on the third message.

[0178] In some example embodiments, the third message and the registration request may further indicate an identifier of the third device, respectively. For example, the identifier of the third device may include at least one of the following items: a subscription hidden identifier, an identifier in a network access identifier format, or an identifier in a globally unique temporary identifier format.

[0179] In some example embodiments, the first apparatus further comprises means for performing other operations in some example embodiments of the method 400 or the first apparatus 201. In some example embodiments, the means comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause execution of the first apparatus.

[0180] In some example embodiments, a second device (eg, Figure 2 The second device 202 in the method 500 may include a component for performing the corresponding operation of the method 500. The component may be implemented in any suitable form. For example, the component may be implemented in a circuit system or a software module. The second device may be implemented as Figure 2 The second device 202 in, or included in Figure 2 In the second device 202.

[0181] In some example embodiments, the second device includes: a component for receiving a registration request for a third device from the first device, the registration request at least indicating that the third device is accessing a network via a non-cellular mechanism; a component for sending an authentication request for the third device to a fifth device, the authentication request at least indicating that the third device is accessing the network via a non-cellular mechanism; and a component for sending a first message to the first device indicating that the third device is authenticated.

[0182] For example, the registration request may include at least one of: an indication of a requirement for an encryption key for the third device, or an indication of a device type of the third device.

[0183] In some example embodiments, the means for sending the first message may further include: means for determining that an authentication process for the third apparatus is successful; and means for sending the first message based on the determination that the authentication process is successful.

[0184] In some example embodiments, the second device may further include a component for receiving an authentication response to the authentication request from the fifth device. The authentication response may indicate that the third device is authenticated. The authentication response may include security information for the third device. In this case, the first message may also include security information.

[0185] Alternatively or additionally, the first message may also include a request for a security mode. In this case, the second device may also include: a component for generating a first key for the first device based on an access type associated with a non-cellular mechanism; a component for receiving a second message indicating completion of the security mode from the first device; and a component for sending the first key to the first device based on receipt of the second message.

[0186] In some example embodiments, the second apparatus further comprises means for performing other operations in some example embodiments of the method 500 or the second apparatus 202. In some example embodiments, the means comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause execution of the second apparatus.

[0187] In some example embodiments, a third device (eg, Figure 2 The third device 203 in the method 600 may include a component for performing the corresponding operation of the method 600. The component may be implemented in any suitable form. For example, the component may be implemented in a circuit system or a software module. The third device may be implemented as Figure 2 The third device 203 in, or included in Figure 2 In the third device 203.

[0188] In some example embodiments, the third device includes: a component for sending a message to at least one of the first device or the fourth device, the message at least indicating that the third device is accessing the network via a non-cellular mechanism; a component for determining security information for establishing a connection between the third device and the fourth device; and a component for performing a process with the fourth device to establish the connection based on the security information.

[0189] In some example embodiments, the message may also indicate an identifier of the third device. For example, the identifier of the third device may include at least one of the following: a subscription hidden identifier, an identifier in a network access identifier format, or an identifier in a globally unique temporary identifier format.

[0190] In some example embodiments, the means for determining the security information may include means for determining the security information based on credentials for the third device. Alternatively or additionally, the means for determining the security information may include means for determining the security information based at least in part on an access type associated with the non-cellular mechanism. In this case, the means for determining the security information may include means for determining the security information based at least in part on the associated access type.

[0191] In some example embodiments, the security information may include one of the following: a session key for the third device, or a pairwise master key for the third device. For example, the session key may include one of the following: a master session key, or an extended master session key.

[0192] In some example embodiments, the third device may further include means for generating a key for communicating with the fourth device based on the security information.

[0193] In some example embodiments, the third apparatus further comprises means for performing other operations in some example embodiments of the method 600 or the third apparatus 203. In some example embodiments, the means comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause execution of the third apparatus.

[0194] In some example embodiments, a fourth apparatus (eg, Figure 2 The fourth device 204 in the method 700 may include a component for performing the corresponding operation of the method 700. The component may be implemented in any suitable form. For example, the component may be implemented in a circuit system or a software module. The fourth device may be implemented as Figure 2 The fourth device 204 in, or included in Figure 2 In the fourth device 204.

[0195] In some example embodiments, the fourth device includes: means for receiving security information for establishing a connection between the third device and the fourth device from the first device; and means for performing a process with the third device to establish the connection based on the security information.

[0196] In some example embodiments, the fourth device may further include means for generating a key for communicating with the third device based on the security information.

[0197] In some example embodiments, the fourth device may also include a component for receiving a first message from the third device, the first message at least indicating that the third device is accessing the network via a non-cellular mechanism; and a component for sending a second message to the first device based on receipt of the first message, the second message at least indicating that the third device is accessing the network via a non-cellular mechanism.

[0198] In some example embodiments, the fourth apparatus further comprises means for performing other operations in some example embodiments of the method 700 or the fourth apparatus 204. In some example embodiments, the means comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause execution of the fourth apparatus.

[0199] In some example embodiments, a fifth apparatus (eg, Figure 2 The fifth device 205 in the method 800 may include a component for performing the corresponding operation of the method 800. The component may be implemented in any suitable form. For example, the component may be implemented in a circuit system or a software module. The fifth device may be implemented as Figure 2 The fifth device 205 is included in Figure 2 In the fifth device 205.

[0200] In some example embodiments, the fifth device includes: a component for receiving a first authentication request for the third device from the second device, the first authentication request at least indicating that the third device is accessing the network via a non-cellular mechanism; and a component for sending a second authentication request for the third device to the sixth device. In some example embodiments, the second authentication request may indicate that the third device is accessing the network via a non-cellular mechanism.

[0201] In some example embodiments, the fifth device may also include a component for generating security information for the second device based on credentials for the third device; a component for determining that the third device is authenticated based on an authentication process initiated by the sixth device; and a component for sending an authentication response to the second device based on the determination that the third device is authenticated, the authentication response indicating that the third device is authenticated and including security information.

[0202] In some example embodiments, the security information may include a session key for the third device. For example, the session key may include one of the following: a master session key, or an extended master session key.

[0203] In some example embodiments, the authentication process may include one of: an Extensible Authentication Protocol Transport Level Security process, an Extensible Authentication Protocol Authentication and Key Agreement process, or a Fifth Generation Mobile Communication Technology Authentication and Key Agreement process.

[0204] In some example embodiments, the fifth apparatus further comprises means for performing other operations in some example embodiments of the method 800 or the fifth apparatus 205. In some example embodiments, the means comprises at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause execution of the fifth apparatus.

[0205] Fig. 9 900 is a simplified block diagram of a device suitable for implementing an example embodiment of the present disclosure. The device 900 may be provided to implement a communication device, such as Figure 1 The terminal device 110, RG 120, W-AGF 130, AMF 140, SEAF 145, AUSF 150 or UDM 160 shown, or Figure 2 The first device 201, the second device 202, the third device 203, the fourth device 204, the fifth device 205 or the sixth device 206 are shown. As shown in the figure, the device 900 includes one or more processors 910, one or more memories 920 coupled to the processor 910, and one or more communication modules 940 coupled to the processor 910.

[0206] The communication module 940 is used for two-way communication. The communication module 940 has one or more communication interfaces to facilitate communication with one or more other modules or devices. The communication interface may represent any interface required for communication with other network elements. In some example embodiments, the communication module 940 may include at least one antenna.

[0207] Processor 910 may be of any type suitable for the local technology network, and may include, as non-limiting examples, one or more of the following: a general purpose computer, a special purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture. Device 900 may have multiple processors, such as application specific integrated circuit chips that are time slaved to a clock synchronized with a main processor.

[0208] The memory 920 may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memories include, but are not limited to, read-only memory (ROM) 924, electrically programmable read-only memory (EPROM), flash memory, hard disks, compact disks (CDs), digital video disks (DVDs), optical disks, laser disks, and other magnetic and / or optical storage devices. Examples of volatile memories include, but are not limited to, random access memory (RAM) 922 and other volatile memories that do not persist during power outages.

[0209] The computer program 930 includes computer executable instructions executed by the associated processor 910. The instructions of the program 930 may include instructions for performing the operations / actions of some example embodiments of the present disclosure. The program 930 may be stored in a memory (e.g., ROM 924). The processor 910 may perform any suitable actions and processes by loading the program 930 into the RAM 922.

[0210] The exemplary embodiments of the present disclosure may be implemented by a program 930 so that the device 900 may execute the Figures 2 to 8 Any process of the present disclosure discussed. The exemplary embodiments of the present disclosure may also be implemented by hardware, or by a combination of software and hardware.

[0211] In some example embodiments, the program 930 may be tangibly contained in a computer-readable medium, which may be included in the device 900 (such as in the memory 920), or in other storage devices accessible to the device 900. The device 900 may load the program 930 from the computer-readable medium to the RAM 922 for execution. In some example embodiments, the computer-readable medium may include any type of non-transitory storage medium, such as ROM, EPROM, flash memory, hard disk, CD, DVD, etc. The term "non-transitory" as used herein is a limitation on the medium itself (i.e., tangible, not a signal), not a limitation on the persistence of data storage (e.g., RAM vs. ROM).

[0212] Fig.10 An example of a computer readable medium 1000 is shown which may be in the form of a CD, DVD or other optical storage disk. The computer readable medium 1000 has a program 930 stored thereon.

[0213] Generally, the various embodiments of the present disclosure may be implemented in hardware or dedicated circuits, software, logic, or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software that may be executed by a controller, microprocessor, or other computing device. Although various aspects of the embodiments of the present disclosure are illustrated and described as block diagrams, flow charts, or using some other graphical representations, it should be understood that, as non-limiting examples, the boxes, devices, systems, techniques, or methods described herein may be implemented in hardware, software, firmware, dedicated circuits or logic, general hardware or controllers or other computing devices, or some combination thereof.

[0214] Some example embodiments of the present disclosure also provide at least one computer program product tangibly stored on a computer-readable medium (such as a non-transient computer-readable medium). The computer program product includes computer executable instructions, such as computer executable instructions included in a program module, which are executed in a device on a target physical or virtual processor to perform any of the above methods. Typically, a program module includes routines, programs, libraries, objects, classes, components, data structures, etc. that perform specific tasks or implement specific abstract data types. In various embodiments, the functions of the program modules can be combined or split between program modules as needed. Machine executable instructions for program modules can be executed in local or distributed devices. In distributed devices, program modules can be located in both local and remote storage media.

[0215] The program code for executing the method of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer or other programmable data processing device so that the program code, when executed by the processor or controller, enables the function / operation specified in the flow chart and / or block diagram to be realized. The program code can be executed completely on the machine, partially on the machine, as an independent software package, partially on the machine and partially on a remote machine, or completely on a remote machine or server.

[0216] In the context of the present disclosure, computer program codes or related data may be carried by any suitable carrier to enable a device, apparatus or processor to perform various processes and operations as described above. Examples of carriers include signals, computer readable media, etc.

[0217] The computer readable medium can be a computer readable signal medium or a computer readable storage medium. The computer readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. A more specific example of a computer readable storage medium will include an electrical connection with one or more wires, a portable computer floppy disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0218] In addition, although operations are described in a particular order, this should not be understood as requiring such operations to be performed in the particular order shown or in sequence, or performing all the operations shown, to obtain the desired result. In some cases, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the above discussion, these should not be interpreted as limitations on the scope of the present disclosure, but rather descriptions of features that may be specific to a particular embodiment. Unless explicitly stated, certain features described in the context of a separate embodiment may also be implemented in combination in a single embodiment. On the contrary, unless explicitly stated, various features described in the context of a single embodiment may also be implemented in multiple embodiments individually or in any suitable sub-combination.

[0219] Although the disclosure has been described in language specific to structural features and / or methodological acts, it should be understood that the disclosure defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.< / mcc> < / mnc> < / mcc> < / mnc>

Claims

1. A first device, comprising: at least one processor; as well as at least one memory storing instructions, which when executed by the at least one processor cause the first device to at least perform: sending a registration request for a third device to a second device, the registration request indicating at least that the third device is accessing a network via a non-cellular mechanism; receiving, from the second device, a first message indicating that the third device is authenticated; as well as Based on the reception of the first message, security information for establishing a connection between the third device and the fourth device is sent to a fourth device.

2. The first device according to claim 1, wherein the registration request comprises at least one of the following: an indication of a requirement for an encryption key for said third device, or An indication of a device type of the third device. The first device according to claim 1 , wherein the first message further includes the security information. 4 . The first device of claim 3 , wherein the security information comprises a session key for the third device.

5. The first device of claim 4, wherein the session key comprises one of the following: Master Session Key, or The extended master session key.

6. The first device of claim 1, wherein the first message further comprises a request for a security mode, and The first device is further configured to execute: based on the receipt of the first message, sending a second message to the second device indicating completion of the security mode; receiving, from the second device, a first key for the first device, the first key being determined by the second device based on an access type associated with the non-cellular mechanism; and Based on the first key, the security information is generated.

7. The first device of claim 6, wherein the security information comprises a pairwise master key for the third device.

8. The first device of claim 1, wherein the first device is further configured to perform: receiving a third message from the third device or the fourth device, the third message at least indicating that the third device is accessing the network via the non-cellular mechanism; and Based on the third message, the registration request is generated.

9. The first device according to claim 8, wherein the third message and the registration request further indicate an identification of the third device, respectively.

10. The first device according to claim 9, wherein the identification of the third device comprises at least one of the following: Subscribe to hidden identifiers, an identifier in the format of a network access identifier, or An identifier in the format of a globally unique temporary identifier.

11. The first device according to claim 1, wherein: The first device includes a wired access gateway function, The second device comprises an access and mobility management function or a security anchor function, The third apparatus comprises a certifiable non-3rd Generation Partnership Project device, and The fourth device includes a residential gateway.

12. A second device, comprising: at least one processor; as well as at least one memory storing instructions, which when executed by the at least one processor cause the second device to at least perform: receiving, from the first device, a registration request for a third device, the registration request indicating at least that the third device is accessing a network via a non-cellular mechanism; sending an authentication request for the third device to a fifth device, the authentication request at least indicating that the third device is accessing the network via the non-cellular mechanism; as well as A first message is sent to the first device indicating that the third device is authenticated.

13. The second device according to claim 12, wherein the registration request comprises at least one of the following: an indication of a requirement for an encryption key for said third device, or An indication of a device type of the third device.

14. The second device according to claim 13, wherein the second device is further configured to execute: An authentication response to the authentication request is received from the fifth device, the authentication response indicating that the third device is authenticated and including security information for the third device. The second device of claim 14 , wherein the first message further includes the security information.

16. The second device of claim 12, wherein sending the first message comprises: Determining that an authentication process for the third device is successful; as well as Based on the determination that the authentication process was successful, the first message is sent.

17. The second device of claim 12, wherein the first message further comprises a request for a security mode, and The second device is further configured to execute: generating a first key for the first device based on an access type associated with the non-cellular mechanism; receiving a second message from the first device indicating completion of the security mode; and Based on the receipt of the second message, the first key is sent to the first device.

18. The second device according to claim 12, wherein: The first device includes a wired access gateway function, The second device comprises an access and mobility management function or a security anchor function, The third apparatus comprises a certifiable non-3rd Generation Partnership Project device, and The fifth means comprises an authentication server function.

19. A third device, comprising: at least one processor; as well as at least one memory storing instructions, which when executed by the at least one processor cause the third device to at least perform: sending a message to at least one of the first device or the fourth device, the message indicating at least that the third device is accessing a network via a non-cellular mechanism; determining security information for establishing a connection between the third device and the fourth device; as well as Based on the security information, a process is performed with the fourth device to establish the connection.

20. The third device according to claim 19, wherein the third device is further configured to execute: Based on the security information, a key for communicating with the fourth device is generated.

21. The third apparatus of claim 19, wherein determining the security information comprises at least one of the following: determining the security information based on credentials for the third device; or The security information is determined based at least in part on an access type associated with the non-cellular mechanism.

22. The third device of claim 19, wherein the message further indicates an identification of the third device.

23. The third device according to claim 22, wherein the identification of the third device comprises at least one of the following: Subscribe to hidden identifiers, an identifier in the format of a network access identifier, or An identifier in the format of a globally unique temporary identifier.

24. The third device according to claim 19, wherein the security information comprises one of the following: a session key for the third device, or A pairwise master key for the third device.

25. The third apparatus according to claim 24, wherein the session key comprises one of the following: Master Session Key, or The extended master session key.

26. The third apparatus of claim 19, wherein the third apparatus comprises a non-3rd Generation Partnership Project certifiable device and the fourth apparatus comprises a residential gateway.

27. A fourth device, comprising: at least one processor; as well as at least one memory storing instructions, which, when executed by the at least one processor, cause the fourth device to at least perform: receiving, from the first device, security information for establishing a connection between the third device and the fourth device; as well as Based on the security information, a process is performed with the third device to establish the connection.

28. The fourth device according to claim 27, wherein the fourth device is further configured to execute: Based on the security information, a key for communicating with the third device is generated.

29. The fourth device according to claim 27, wherein the fourth device is further configured to execute: receiving a first message from the third device, the first message indicating at least that the third device is accessing a network via a non-cellular mechanism; and Based on the receipt of the first message, a second message is sent to the first device, the second message indicating at least that the third device is accessing the network via the non-cellular mechanism.

30. The fourth device according to claim 27, wherein: The first device includes a wired access gateway function, The third apparatus comprises a certifiable non-3rd Generation Partnership Project device, and The fourth device includes a residential gateway.

31. A fifth device, comprising: at least one processor; as well as at least one memory storing instructions, which, when executed by the at least one processor, cause the fifth device to at least perform: receiving, from a second device, a first authentication request for a third device, the first authentication request indicating at least that the third device is accessing a network via a non-cellular mechanism; and A second authentication request for the third device is sent to a sixth device.

32. The fifth device of claim 31, wherein the second authentication request indicates that the third device is accessing the network via the non-cellular mechanism.

33. The fifth apparatus according to claim 31, wherein the fifth apparatus is further configured to execute: generating security information for the third device based on the credentials for the third device; Based on the authentication process initiated by the sixth device, determining that the third device is authenticated; and Based on the determination that the third device is authenticated, an authentication response is sent to the second device, the authentication response indicating that the third device is authenticated and including the security information.

34. The fifth device of claim 33, wherein the security information comprises a session key for the third device.

35. The fifth apparatus according to claim 34, wherein the session key comprises one of the following: Master Session Key, or The extended master session key.

36. The fifth apparatus according to claim 31, wherein the authentication process comprises one of the following: Extensible Authentication Protocol transport-level security process, Extensible Authentication Protocol authentication and key agreement process, or Authentication and key negotiation process for fifth generation mobile communication technology.

37. The fifth device according to claim 31, wherein: The second device comprises an access and mobility management function or a security anchor function, the third device comprising a certifiable non-3rd Generation Partnership Project device, The fifth device comprises an authentication server function, and The sixth device includes unified data management.

38. A method comprising: sending, from the first device to the second device, a registration request for a third device, the registration request indicating at least that the third device is accessing a network via a non-cellular mechanism; receiving, from the second device, a first message indicating that the third device is authenticated; as well as Based on the reception of the first message, security information for establishing a connection between the third device and the fourth device is sent to a fourth device.

39. A method comprising: receiving, by the second device from the first device, a registration request for a third device, the registration request at least indicating that the third device is accessing a network via a non-cellular mechanism; sending an authentication request for the third device to a fifth device, the authentication request at least indicating that the third device is accessing the network via the non-cellular mechanism; as well as A first message is sent to the first device indicating that the third device is authenticated.

40. A method comprising: sending a message from a third device to at least one of the first device or the fourth device, the message indicating at least that the third device is accessing a network via a non-cellular mechanism; determining security information for establishing a connection between the third device and the fourth device; as well as Based on the security information, a process is performed with the fourth device to establish the connection.

41. A method comprising: receiving, by the fourth device from the first device, security information for establishing a connection between the third device and the fourth device; as well as Based on the security information, a process is performed with the third device to establish the connection.

42. A method comprising: receiving, by a fifth device, from a second device, a first authentication request for a third device, the first authentication request at least indicating that the third device is accessing a network via a non-cellular mechanism; as well as A second authentication request for the third device is sent to a sixth device.

43. A computer-readable medium comprising instructions stored thereon, the instructions being configured to cause an apparatus to perform at least the method of claim 38, the method of claim 39, the method of claim 40, the method of claim 41, or the method of claim 42.